Description
A vulnerability was detected in Releasit Releasit COD Form & Upsells v1. This vulnerability affects unknown code of the component OTP Validation. The manipulation results in client-side enforcement of server-side security. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version v2 is able to resolve this issue. The affected component should be upgraded.
Published: 2026-09-01
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the OTP Validation component of Releasit COD Form & Upsells version 1. By manipulating the client‑side handling of one‑time passwords, an attacker can cause the application to rely on data supplied by the client instead of performing the intended server‑side verification. This flaw turns server‑side security controls into a flag that can be toggled by the user, effectively bypassing authentication and permitting access to coupon or upsell functionality that is normally gated by merchant code. The weakness is identified as CWE‑602, which describes the improper reliance on client‑side validation for securing a system.

Affected Systems

The affected product is Releasit COD Form & Upsells v1, distributed by the vendor Releasit. The SOP includes a client‑side OTP enforcement module that is missing in the upgraded v2 release; upgrading to that version removes the problematic component and reinstates proper server‑side OTP checks. No other versions were listed as vulnerable in the CNA data, so at present only v1 is known to be affected.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and the EPSS score is not available, which means the exploitation probability is not quantified. The vulnerability is not listed in CISA’s KEV catalog, so no wide‑scale exploitation has been reported. However, the description explicitly states that the attack may be launched remotely and that the exploit has already been made public. Because the flaw is client‑side, once the vulnerability is known it can be exploited with minimal effort and without special access, elevating the operational risk for merchants running affected installations.

Generated by OpenCVE AI on September 1, 2026 at 16:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Releasit COD Form & Upsells to version 2 to eliminate the client‑side OTP validation flaw.
  • Ensure that the new installation enforces OTP validation exclusively on the server side and confirm that no client‑side bypass mechanisms remain.
  • Implement monitoring and rate‑limiting on authentication and upsell endpoints to detect and mitigate repeated exploitation attempts.

Generated by OpenCVE AI on September 1, 2026 at 16:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Releasit Releasit COD Form & Upsells v1. This vulnerability affects unknown code of the component OTP Validation. The manipulation results in client-side enforcement of server-side security. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version v2 is able to resolve this issue. The affected component should be upgraded.
Title Releasit Releasit COD Form & Upsells OTP Validation client-side enforcement of server-side security
First Time appeared Releasit
Releasit releasit Cod Form Upsells
Weaknesses CWE-602
CPEs cpe:2.3:a:releasit:releasit_cod_form_upsells:*:*:*:*:*:*:*:*
Vendors & Products Releasit
Releasit releasit Cod Form Upsells
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Releasit Releasit Cod Form Upsells
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-04T01:53:54.399Z

Reserved: 2026-09-01T07:08:59.968Z

Link: CVE-2026-84110

cve-icon Vulnrichment

Updated: 2026-09-04T01:53:45.442Z

cve-icon NVD

Status : Deferred

Published: 2026-09-01T15:17:40.983

Modified: 2026-09-04T02:17:19.630

Link: CVE-2026-84110

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T16:27:55Z

Weaknesses
  • CWE-602

    Client-Side Enforcement of Server-Side Security